Windows: Uncommon Process Deletes Zone.Identifier Alternate Data Stream (ADS)

Alert on deletion of the Zone.Identifier ADS by an uncommon process on Windows.

FreeUnreviewedSigmamediumv1
title: "Windows: Uncommon Process Deletes Zone.Identifier Alternate Data Stream (ADS)"
id: 2f56e404-f457-4068-adfe-4530c4867a2e
related:
  - id: 7eac0a16-5832-4e81-865f-0268a6d19e4b
    type: similar
  - id: 3109530e-ab47-4cc6-a953-cac5ebcc93ae
    type: derived
status: test
description: This rule flags Windows file deletions targeting the Zone.Identifier alternate data stream, when performed by a process not commonly expected to manage it. Attackers may remove this ADS to reduce security controls and hinder analysis methods that rely on the marker. It relies on Windows file deletion telemetry that includes the target filename/ADS name and the initiating process image path.
references:
  - https://securityliterate.com/how-malware-abuses-the-zone-identifier-to-circumvent-detection-and-analysis/
  - Internal Research
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_delete/file_delete_win_zone_identifier_ads_uncommon.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-09-04
modified: 2025-07-04
tags:
  - attack.stealth
  - attack.t1070.004
logsource:
  product: windows
  category: file_delete
detection:
  selection:
    TargetFilename|endswith: :Zone.Identifier
  filter_main_generic:
    Image:
      - C:\Program Files\PowerShell\7-preview\pwsh.exe
      - C:\Program Files\PowerShell\7\pwsh.exe
      - C:\Windows\explorer.exe
      - C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
      - C:\Windows\SysWOW64\explorer.exe
      - C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
  filter_optional_browsers_chrome:
    Image:
      - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      - C:\Program Files\Google\Chrome\Application\chrome.exe
  filter_optional_browsers_firefox:
    Image:
      - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      - C:\Program Files\Mozilla Firefox\firefox.exe
  filter_optional_browsers_msedge:
    Image:
      - C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
      - C:\Program Files\Microsoft\Edge\Application\msedge.exe
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Other third party applications not listed.
level: medium
license: DRL-1.1

What it detects

This rule flags Windows file deletions targeting the Zone.Identifier alternate data stream, when performed by a process not commonly expected to manage it. Attackers may remove this ADS to reduce security controls and hinder analysis methods that rely on the marker. It relies on Windows file deletion telemetry that includes the target filename/ADS name and the initiating process image path.

Known false positives

  • Other third party applications not listed.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.